Decryption rule monitor action

The Monitor action is not designed to permit or deny traffic. Rather, its primary purpose is to force connection logging, regardless of how matching traffic is eventually handled. The ClientHello message is not modified if traffic matches a Monitor rule condition.

Monitor action traffic handling

Traffic that matches a Monitor rule is processed in this sequence:

  1. Traffic matches the Monitor rule condition and connection logging is forced.

  2. Traffic is then matched against additional rules, if present, to determine whether to trust, block, or decrypt it.

  3. The first non-Monitor rule matched determines traffic flow and any further inspection.

  4. If there are no additional matching rules, the system uses the default action.

The system automatically logs end-of connection events for monitored traffic to the Security Cloud Control database, regardless of the logging configuration of the rule or default action that later handles the connection.